Hi Umamaheshwar,
Welcome to the world of AQL! If you're looking to sort source IP addresses based on the total event count, here's a basic AQL query you can start with:
aql
- Copy
- Edit
- SELECT sourceip, COUNT(*) as event_count
- FROM events
- GROUP BY sourceip
- ORDER BY event_count DESC
This query will:
- Count the number of events for each sourceip
- Group them accordingly
- Sort the result in descending order based on event count
You can now use this as a foundation and add more filters or conditions as needed.
Let me know if you need help customizing it further!
Best,
RHJ
------------------------------
Rh Jaffery
------------------------------